Tue 21 Jul 2026 / 12:46 ET
Kernel
Security 2 min read

Kenya investigates defacement of Ruto website with bitcoin ransom demand

Kenyan officials say the president’s website was briefly defaced, but they have found no evidence that sensitive data was accessed or stolen.

Mara Chen-Doyle

By Mara Chen-Doyle / Staff Writer

Kenya investigates defacement of Ruto website with bitcoin ransom demand
img: The Record

Kenya is investigating a cyberattack on President William Ruto’s official website after the site displayed an anti-government ransom note demanding five bitcoin, worth about $330,000.

The incident took place on Saturday and affected the public-facing presidential website. Screenshots circulated on social media showed a defaced homepage with a cryptocurrency wallet address and a threat to publish unspecified information about Ruto if the ransom was not paid.

By Monday, the site was reachable again, Techpoint Africa reported. Kenyan officials have not named a suspect, and there is no public evidence that the attackers obtained or released any government data.

William Kabogo, Kenya’s Cabinet Secretary for Information, Communications and the Digital Economy, confirmed the incident over the weekend and said government cybersecurity teams were examining the attack.

“As a precautionary measure, access to the Presidential website was temporarily restricted to facilitate containment, forensic analysis and restoration efforts,” Kabogo said in a statement.

Kabogo said authorities had not found evidence that sensitive data was accessed without authorization, removed from systems or lost. He also said government systems and digital services remained secure and operational.

Defacement, ransom note, unclear access

On the facts disclosed so far, the visible compromise was a website defacement: attackers altered what visitors saw on the site and used that space to post a demand. That is different from proving the attackers had deeper access to presidential systems or private files.

The message shown in screenshots claimed it was the attackers’ “third” warning to the president before a data release. Kenyan authorities have not validated that claim, and no verified leak linked to the incident has been made public.

The bitcoin demand also does not prove the attackers had data worth extorting. Ransom messages often try to create pressure before any evidence of theft appears. In this case, Kabogo’s public statement says investigators had found no sign of data exfiltration.

Kenyan government sites have been targeted before

The attack follows earlier disruptions to Kenyan government websites. In November 2025, a coordinated cyberattack temporarily knocked multiple government sites offline or altered their pages, including sites tied to the presidency and ministries responsible for interior, health, education, energy, labor and water.

During that earlier incident, several ministry websites were defaced with white supremacist slogans, including “We will rise again,” “White power worldwide,” and “14:88 Heil Hitler.”

Kenyan officials have not said whether the latest incident has any connection to the November 2025 attack. The available public record points only to another compromise of a government web presence, a ransom demand in bitcoin and an investigation that, so far, has not produced evidence of stolen sensitive information.

This story draws on original reporting from The Record.

More Security/

view all ↗